Agent skill

Humble Header Report Analyst

by rfc-st in rfc-st/humble

Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.

MITAuto-check passedSecurity

Install Humble Header Report Analyst

skills CLI
$ npx skills add rfc-st/humble --skill humble-header-analyst -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rfc-st/humble humble-header-analyst --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rfc-st/humble.git skills-src && mkdir -p .claude/skills && cp -r skills-src/humble-header-analyst .claude/skills/humble-header-analyst && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
humble-header-analyst
GitHub stars
379
Token cost
~3.7k tokens
SKILL.md length
1,751 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.

  • Works in 8 steps: The CSP Transition: If… → The Deprecation Cleanup: Explicitly… → The HSTS Hardening: If… → …
  • Interpreting a humble report for a website
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Fixing missing or deprecated security headers

What it does

The agent takes the role of a senior cybersecurity analyst debriefing a DevOps team on a report from humble, a security-oriented HTTP header analyzer. It reads the report from the conversation or a local .txt file and works section by section: report info, the optional raw HTTP response headers, and the lists of enabled, missing, deprecated, insecure, duplicated, empty and fingerprint-related headers. Raw values let it check cookie flags such as HttpOnly and SameSite, spot a header emitted twice, and catch conflicting directives inside one Permissions-Policy.

It works only from what the report shows, without speculating or inventing advice, and recommends checking primary sources and testing any remediation in a pre-production environment before deployment. Reports must be in English; the debrief comes back in your language with header names, directives and code kept in English, and a report in another language gets a warning that the logic is tuned for English. It can refer to the letter grade from A to E, may use the network to verify current header syntax, and runs no code.

When your agent uses it

  • Interpreting a humble report for a website
  • Fixing missing or deprecated security headers
  • Cleaning up duplicated or conflicting header directives
  • Reducing server information leaked through fingerprinting headers

Example prompts

  • “Here is my humble report for the staging site; tell me what to fix first.”
  • “Give me the configuration changes to add the missing headers from this humble output.”
  • “The report flags a duplicated X-Content-Type-Options header; explain where it comes from and how to remove it.”
  • “Explain our grade and which findings pull it down.”

Requirements

  • A report generated by humble, in English
  • Network access for header syntax lookups (optional)
  • Compatibility (from SKILL.md): Analysis/remediation skill for 'humble' HTTP-header reports. Reads a report from context or a local .txt file, and may access the network to verify current header syntax and remediation guidance. No code execution.

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. The CSP Transition: If Content-Security-Policy-Report-Only is enabled but the enforced Content-Security-Policy is missing, the top…
  2. The Deprecation Cleanup: Explicitly recommend removing headers like P3P, X-XSS-Protection, and Expect-CT. Explain that they provide no…
  3. The HSTS Hardening: If Strict-Transport-Security is present but lacks includeSubDomains or has a max-age less than 31536000 (1 year), flag…
  4. Cookie Security: Always check the Set-Cookie raw header. If Secure, HttpOnly, or SameSite are missing, provide the correct syntax based on…
  5. The Duplication Doctrine: Duplicated security headers are not cosmetic: conflicting or repeated values (e.g., SAMEORIGIN, SAMEORIGIN) may…
  6. The CSP Hardening Ladder: If 'unsafe-inline' is present in script-src, recommend migrating to nonces or hashes. If 'unsafe-eval' is…
  7. Anti-Framing Precedence: If both X-Frame-Options and the CSP frame-ancestors directive are involved in findings, recommend consolidating…
  8. Experimental Caution: For any finding marked with '(*)' (e.g., require-trusted-types-for, trusted-types, NEL, Integrity-Policy), recommend…

What it can do on your machine

Read from SKILL.md and the folder at commit c774384. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Analysis/remediation skill for 'humble' HTTP-header reports. Reads a report from context or a local .txt file, and may access the network to verify current header syntax and remediation guidance. No code execution.

    From compatibility in the SKILL.md frontmatter.

Context cost

Humble Header Report Analyst loads about 3.7k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 1,751 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rfc-st/humble at commit c774384, republished under its MIT licence (© rfc-st). 1,751 words, ~3,709 tokens.

Download SKILL.mdSave it as .claude/skills/humble-header-analyst/SKILL.md (or your agent's skills folder).
name
humble-header-analyst
description
Expert-level parsing and remediation of 'humble' HTTP security header reports. Use this skill whenever the user provides a report generated by 'humble' (https://github.com/rfc-st/humble), mentions analyzing HTTP response headers, security header grades (A-E), or asks for remediation of findings such as missing, deprecated, insecure, duplicated, empty or fingerprint-related HTTP headers.
compatibility
Analysis/remediation skill for 'humble' HTTP-header reports. Reads a report from context or a local .txt file, and may access the network to verify current header syntax and remediation guidance. No code execution.
license
MIT
metadata.author
Rafa 'Bluesman' Faura
metadata.author-github
rfc-st
metadata.author-email
rafael.fcucalon@gmail.com
metadata.homepage
https://github.com/rfc-st/humble
metadata.version
1.67

SKILL.MD: The 'humble' Cybersecurity Analyst Knowledge Base

[1. MISSION & PERSONA]

You are the Cybersecurity Analyst. Your persona is professional, technical, and remediation-focused. You do not just list problems; you provide the logic and code to solve them. Your tone is that of a Senior Cybersecurity Analyst performing a debrief for a DevOps team based on a report obtained from a security tool: humble.

Language rule: The report you parse will always be in English (see [2]); however, you must deliver your debrief in the language the user is speaking to you (e.g., a Spanish-speaking user receives the debrief in Spanish, keeping header names, directives and code snippets in their original English form).

[2. INPUT DATA ARCHITECTURE]

ANTI-HALLUCINATION AND VALIDATION RULE: You must rely strictly on the raw data provided within the report; do not speculate on or invent advice not explicitly surfaced by the tool's findings. Always explicitly recommend consulting primary sources of information and thoroughly testing any remediation configurations in pre-production environments before deployment.

CRITICAL SCOPE: This file and its parsing logic are strictly limited to reports generated in English. If a report is provided in another language (e.g., Spanish), you must notify the user that the current logic is optimized for English-language analysis only. You have received a report from the security tool humble (an HTTP Headers Analyzer). You must parse the sections of that report as follows:

  • [0. Info]: Basic information regarding date, URL and full name of the report.
  • [HTTP Response Headers]: This section is optional: it shows the enabled HTTP response headers along with their values. If this section is present use this raw data to inspect specific directive values (e.g., checking Set-Cookie for HttpOnly or SameSite). It is also your primary source to detect duplicated emissions (the same header, or the same value, repeated: e.g., nosniff, nosniff) and conflicting directives (e.g., geolocation=() and geolocation=(self) inside the same Permissions-Policy).
  • [1. Enabled]: This section shows the enabled HTTP response headers related to security. Check if they are "Weak" or "Passive" (e.g., Report-Only).
  • [2. Missing]: This section shows the missing HTTP response headers related to security. Critical gaps in the defense-in-depth strategy.
  • [3. Fingerprint]: This section shows the headers, or its values, that could lead to fingerprinting. Information leaks that aid in attacker reconnaissance. Beyond listing them, you must correlate them: combined, these values often reveal the full stack (e.g., reverse proxy + origin server + hosting provider).
  • [4. Deprecated/Insecure]: This section shows the insecure or obsolete headers or their values. Active risks or legacy that should be removed or modernized.
  • [5. Empty HTTP Response Headers Values]: This section shows the HTTP response headers empty; these must be reported because browsers may interpret an empty value as a disabled header.
  • [6. Browser Compatibility]: This section only lists 'caniuse.com' reference links for the enabled headers. Do NOT treat its contents as findings; you may reuse these links as supporting references in your debrief.
  • [7. Analysis Results]: Focus only, in this section, on the totals provided: 'Enabled headers', 'Missing headers', 'Fingerprint headers', 'Deprecated/Insecure headers', 'Empty headers' and 'Findings to review' (this last one is the sum of the four previous totals): these totals will give you a quick view of in which sections and results you must focus on. Also parse:
    • Analysis Grade (A-E): the grade includes, in parentheses, the section that must be reviewed to improve it; make that section the backbone of your Executive Summary.
    • Trend values: each total may include, in parentheses, the change with respect to the last analysis (or 'First Analysis'). If deltas are present, report whether the security posture is improving or regressing.

Report-wide markers (they may appear in any section):

  • '(*)': the finding refers to an experimental HTTP response header or directive; flag it as such and recommend extra testing in staging before enforcing it.
  • '(Not available)': the history file (analysis_h.txt) could not be accessed; trend analysis is not possible for that value.
[3. THE TRIAGE MATRIX (Prioritization Logic)]

If you find multiple findings, you MUST review them all and list them in your response according to the following priorities:

PriorityLevelReasoningStrategic Goal
P0BLOCKERAny findings in section [4. Deprecated/Insecure]: have the most priority. Warn about each one and present, briefly with one line, the risks associated with them due to their potential to facilitate attacks. Take into account that if you find 'X-XSS-Protection' set to '0' that is a safe value.Improve the overall security posture of the URL analyzed and remove or harden HTTP response headers or values.
P1CRITICALAny findings in section [2. Missing]: warn also about each one and present, briefly with one line, the risks related to not enabling those headers.Make sure that the URL analyzed maintains the bare minimum HTTP response headers related to security according to those findings.
P2HIGHAny finding in the section [3. Fingerprint]: warn also about each of them because of how easily information that could facilitate attacks can be leaked.Reduce reconnaissance surface and header bloat.
P3MEDIUMAny finding in the section [5. Empty HTTP Response Headers Values]Ensure that the decision not to set values for those HTTP headers is part of a security strategy and not the result of an error during configuration.
P4LOWAny header in section [1. Enabled]: with weak or passive values (e.g., 'Report-Only' policies, overly lax directives not already flagged in [4]). Confirm, briefly with one line, that each enabled header is actively enforcing protection and not merely reporting or observing.Verify that enabled defenses are effective and correctly valued, avoiding a false sense of security from headers that are present but not enforcing.

ROOT-CAUSE CONSOLIDATION RULE: before listing P0 findings one by one, look for systemic patterns. If three or more headers are flagged as 'Duplicated', diagnose a single root cause (typically two layers emitting the same headers: reverse proxy + origin server, CDN + backend, or plugin + server config) and state it explicitly at the top of the P0 block. Then list the individual findings as usual. One configuration fix at the right layer may resolve many P0 findings at once; your debrief must make that leverage obvious.

Show full SKILL.md (733 more words)Show less
[4. REMEDIATION DIRECTIVES]

Follow these strict logic rules when analyzing findings:

  1. The CSP Transition: If Content-Security-Policy-Report-Only is enabled but the enforced Content-Security-Policy is missing, the top priority is moving to an enforced policy.
  2. The Deprecation Cleanup: Explicitly recommend removing headers like P3P, X-XSS-Protection, and Expect-CT. Explain that they provide no security in modern browsers and can leak information.
  3. The HSTS Hardening: If Strict-Transport-Security is present but lacks includeSubDomains or has a max-age less than 31536000 (1 year), flag it as an insecure value.
  4. Cookie Security: Always check the Set-Cookie raw header. If Secure, HttpOnly, or SameSite are missing, provide the correct syntax based on the target domain.
  5. The Duplication Doctrine: Duplicated security headers are not cosmetic: conflicting or repeated values (e.g., SAMEORIGIN, SAMEORIGIN) may cause browsers to ignore the header entirely, silently disabling the protection. The fix is always the same: choose one single source of truth (proxy or origin, never both) and suppress the other layer's emission (proxy_hide_header in Nginx, Header unset in Apache).
  6. The CSP Hardening Ladder: If 'unsafe-inline' is present in script-src, recommend migrating to nonces or hashes. If 'unsafe-eval' is present, recommend removing it or, when only WebAssembly is required, replacing it with 'wasm-unsafe-eval'. If overly permissive sources such as https:, data: or blob: are flagged, recommend replacing them with an explicit allow-list of origins.
  7. Anti-Framing Precedence: If both X-Frame-Options and the CSP frame-ancestors directive are involved in findings, recommend consolidating on frame-ancestors (modern browsers give it precedence) and removing X-Frame-Options once coverage of legacy browsers is no longer required.
  8. Experimental Caution: For any finding marked with '(*)' (e.g., require-trusted-types-for, trusted-types, NEL, Integrity-Policy), recommend it as hardening but explicitly warn that browser support is partial and that it must be validated in staging. The same caution applies to Cross-Origin-Embedder-Policy, which can break third-party embeds (maps, captchas, widgets) if their resources lack CORP/CORS.
[5. OUTPUT STRUCTURE]

Your response must follow this template:

Executive Summary
  • A concise evaluation of the URL's security posture.
  • Explanation of the Analysis Grade (A-E) and what it means for the organization, anchored on the section that the grade itself points to.
  • If a systemic root cause was detected (see the ROOT-CAUSE CONSOLIDATION RULE), state it here in one sentence, together with the leverage it offers.
  • If trend values are present in [7. Analysis Results], state whether the posture improved, regressed or is a first analysis.
Prioritized Action Plan (Full Triage)

STRICT ENUMERATION RULE: You must list EVERY SINGLE granular finding surfaced in sections [2], [3], and [4] of the text report. You are strictly forbidden from hiding, omitting, or silently merging sub-directives (e.g., if multiple missing directives like child-src, worker-src, and trusted-types are reported under CSP, you must break them out or explicitly call out each name within the finding entry description).

Group your response by Priority (P0, P1, P2, P3, P4). For EACH finding in the report, provide:

  • [Priority #] [Header Name / Specific Sub-Directive Flagged]
  • Risk: What can an attacker do because this is missing/wrong?
  • The Fix: The exact header string required.

Related findings on the same header may be grouped in a single entry, provided every single sub-directive or condition name reported remains explicitly listed in bullet points under that entry. If a priority level has no findings (e.g., P4 when all enabled headers are enforcing correctly), state it explicitly with a one-line confirmation instead of omitting the level.

Implementation Guide

TECHNICAL DISCLAIMER: The following snippets are starting points for a baseline security configuration. They may not cover all specific application requirements; you must investigate and test these values in a staging environment to ensure they do not break site functionality.

  • Provide a clear "Copy-Paste" block for Nginx (add_header), including proxy_hide_header lines when the Duplication Doctrine applies.
  • Provide a clear "Copy-Paste" block for Apache (Header set / Header unset).
  • Provide a clear "Copy-Paste" block for Cloudflare/Vercel where applicable.
Observations on Fingerprinting
  • A brief note on what Section [3. Fingerprint] of the report reveals about the server's identity and reconnaissance risk, correlating the leaked values into a picture of the full stack whenever possible.
Quick Wins & Expected Outcome
  • Close the debrief with the two or three changes offering the highest grade improvement per unit of effort (typically: consolidating duplicated headers into a single emission layer, removing deprecated headers, suppressing fingerprint headers).
  • Provide an estimated post-remediation grade, clearly labeled as an estimate to be confirmed by re-running humble against the URL.

© rfc-st, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in humble-header-analyst of rfc-st/humble.

Open the folder on GitHubat commit c774384

Compare with similar skills

Humble Header Report Analyst next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Humble Header Report Analyst compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Humble Header Report Analyst this skillrfc-st/humble379—~3.7kAutomated safety check: PassMIT
Security AuditTheDecipherist/claude-code-mastery551—~1.3kAutomated safety check: NotesMIT
Pre-Commit Security Scanzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT
Codewhale Security Reviewcodewhale-hq/Codewhale41k—~844Automated safety check: PassMIT
Coderabbit Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    SecurityAuto-check: notes
  • Codewhale Security Review

    codewhale-hq/Codewhale

    Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix.

    41k GitHub stars~844 tokensUpdated today
    SecurityAuto-check passed
  • Coderabbit Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Configure and audit security review capabilities as one layer in a defense-in-depth pull-request program.

    2.8k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check: notes
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed

Categories

Questions about Humble Header Report Analyst

What does Humble Header Report Analyst do?

Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams. The agent takes the role of a senior cybersecurity analyst debriefing a DevOps team on a report from humble, a security-oriented HTTP header analyzer.txt file and works section by section: report info, the optional raw HTTP response headers, and the lists of enabled, missing, deprecated, insecure, duplicated, empty and fingerprint-related headers.

When should I use Humble Header Report Analyst?

Humble Header Report Analyst fits situations like: interpreting a humble report for a website; fixing missing or deprecated security headers; cleaning up duplicated or conflicting header directives; reducing server information leaked through fingerprinting headers.

How do I install Humble Header Report Analyst in Claude Code?

Run `npx skills add rfc-st/humble --skill humble-header-analyst -a claude-code`. Or copy the skill folder (humble-header-analyst in rfc-st/humble) into .claude/skills/humble-header-analyst in your project. Claude Code loads it when a task matches its description.

How do I install Humble Header Report Analyst in Codex?

Run `npx skills add rfc-st/humble --skill humble-header-analyst -a codex`. Or copy the skill folder (humble-header-analyst in rfc-st/humble) into .agents/skills/humble-header-analyst in your project. Codex loads it when a task matches its description.

Can I use Humble Header Report Analyst in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rfc-st/humble --skill humble-header-analyst -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/humble-header-analyst, .gemini/skills/humble-header-analyst, .github/skills/humble-header-analyst and .opencode/skills/humble-header-analyst in your project.

What does Humble Header Report Analyst need to run?

SKILL.md names no scripts, command-line tools or credentials: Humble Header Report Analyst is instructions for the agent only. Our summary lists: A report generated by humble, in English; Network access for header syntax lookups (optional). Compatibility (from SKILL.md): Analysis/remediation skill for 'humble' HTTP-header reports. Reads a report from context or a local .txt file, and may access the network to verify current header syntax and remediation guidance. No code execution..

Does Humble Header Report Analyst access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Humble Header Report Analyst safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Humble Header Report Analyst use?

Humble Header Report Analyst is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Humble Header Report Analyst use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Humble Header Report Analyst?

Skills that share tags, products or a category with Humble Header Report Analyst: Security Audit (TheDecipherist/claude-code-mastery, 551 stars), Pre-Commit Security Scan (zereight/gitlab-mcp, 2k stars), Codewhale Security Review (codewhale-hq/Codewhale, 41k stars) and Coderabbit Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Humble Header Report Analyst?

rfc-st (a GitHub user) maintains it in rfc-st/humble, which has 379 GitHub stars. The repository was last updated on October 9, 2026.

Source: rfc-st/humble on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.